Couldn't figure out why cross-vault replay wasn't a bigger documented concern here, until I actually traced the specific binding mechanism underneath it.
The documentation is specific about this: each Universal Challenger commitment binds to that individual vault's own Pre-PegIn HTLC output — not to the challenger set generally, not to any shared or reusable template that could theoretically apply across multiple vaults at once.
A valid challenge-transaction constructed for one vault genuinely cannot apply to a different vault, even a vault created by the same depositor, using the same Universal Challenger set, around the same time. The binding itself prevents that structurally, at the transaction-construction level.
Where the real power actually sits: in that binding mechanism itself, not in any party's discretion, honesty, or careful bookkeeping. Cross-vault replay isn't prevented by policy, by trust, or by anyone remembering to check. It's prevented by the transaction simply not being valid anywhere else, full stop.
Does knowing that prevention lives in the transaction structure itself, rather than in policy anyone could theoretically violate, change how much confidence you'd place in it holding under real adversarial pressure?
@BabylonLabs_io $BABY
#baby
$HEI
$BULLA
The documentation is specific about this: each Universal Challenger commitment binds to that individual vault's own Pre-PegIn HTLC output — not to the challenger set generally, not to any shared or reusable template that could theoretically apply across multiple vaults at once.
A valid challenge-transaction constructed for one vault genuinely cannot apply to a different vault, even a vault created by the same depositor, using the same Universal Challenger set, around the same time. The binding itself prevents that structurally, at the transaction-construction level.
Where the real power actually sits: in that binding mechanism itself, not in any party's discretion, honesty, or careful bookkeeping. Cross-vault replay isn't prevented by policy, by trust, or by anyone remembering to check. It's prevented by the transaction simply not being valid anywhere else, full stop.
Does knowing that prevention lives in the transaction structure itself, rather than in policy anyone could theoretically violate, change how much confidence you'd place in it holding under real adversarial pressure?
@BabylonLabs_io $BABY
#baby
$HEI
$BULLA

